CVE-2013-2240: Menalto Gallery
High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.
lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.
Affected products
- Menalto Gallery: version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; version 3.0.5 only; …
Published 2013-10-10. Last modified 2026-06-16.